Zolteria Privacy Notice
|
Last Updated – 29 April 2026
1. Overview
Zolteria (“we, us, our”) is a data protection compliance platform where data sharing is reimagined. Zolteria is designed to provide a variety of tools that organisations can use to make data protection compliance seamless by streamlining creation, management and approval of information sharing agreements and beyond, including (but not limited to) Data Sharing Agreements, Data Processing Agreements, Data Sharing Frameworks and Data Sharing Specifications. The platform includes a secure, centralised environment with a full library of pre-approved, ready-to-use, and customisable templates, allowing organisations to manage and monitor all agreements seamlessly. Members of the public can also use Zolteria to exercise their data subject rights and manage their data sharing preferences by submitting their requests to relevant organisations, as well as record their interest to be contacted in the future to participate in research projects conducted by partner organisations.
Zolteria is wholly owned by Information Governance Services Ltd (“IGS”), which is incorporated in England and Wales with the company number 11779744 and whose registered address is Furlong House, 10A Chandos Street, London, United Kingdom, W1G 9DQ.
This Privacy Notice explains what information we will be collecting about you and why, how that information will be used, how we keep it safe, and what your rights are around the data we collect and use.
This Privacy Notice covers any personal data we process when you have:
set up an account on Zolteria to make use of our services; or
interacted with our website and have consented to the use of our cookies.
Personal data is information relating to identified or identifiable person which means information we collect about you which can be used to draw conclusions about your identity.
We take our responsibilities under the UK General Data Protection Regulation (UK GDPR), Data (Use and Access) Act 2025, Data Protection Act 2018 and Privacy and Electronic Communications Regulations 2003 as amended by European Directive 2009/136/EC (collectively referred to as “data protection laws”) very seriously. You can be assured that your information will always be used appropriately, lawfully and in line with the applicable data protection laws. We will store your data securely with appropriate safeguards in place to protect it against unauthorised or unlawful processing and ensure that we do not store any of your data for longer than it is strictly necessary to do so.
In most instances, due to the nature of our services, we act as a “data controller”, that is, we collect personal data for our own purposes. A data controller under the UK GDPR is the entity or natural person determining the purposes and means of the processing. In other words, we decide why and how the personal data is used. For example, we act as a data controller in relation to the data that you submit to us when creating an account on Zolteria.
However, there are limited instances where we may act as a “data processor”, where we handle personal data on behalf of other entities acting as data controllers. Where we act as a data processor, we only use personal data in line with the instructions that we receive from the data controller. For example, we act as a data processor where our partner organisations contact you about recruitment into a research project that they are sponsoring, if you have agreed to be contacted. Under the UK GDPR, the data controllers are required to inform you about their activities concerning your personal information. Therefore, where relevant we will refer you to their website and privacy policy.
2. What personal data do we collect, why do we collect it?
Zolteria uses personal data only where it is strictly necessary to do so for our purposes. When you create an account on Zolteria as an Organisation Member (e.g. Admin, User, Data Protection Professional, Healthcare Specialist, Researcher), we may collect the following information:
Some personal data are sensitive and are, therefore, classified as ‘special category of personal data’ under the UK GDPR. Because of their sensitive nature, special categories of personal data are treated differently under the UK GDPR and Article 9 of the UK GDPR prohibits processing of special category data unless one of the conditions for processing is satisfied. We may occasionally collect personal data which falls under this category. When we do this, we will rely on one of the exceptions and conditions under Article 9 of the UK GDPR as set out in the table below.
If you create an account on Zolteria as a Public Member for the purposes of managing your data subject rights and data sharing preferences, we may collect the following information:
For marketing purposes, such as marketing communications and forms, we may collect the following information:
We intend to rely on our legitimate interests to process some categories of your personal data. Our interests are in accordance with data protection laws as it is legitimate for us to maintain our services to the highest possible standards, and they are not overridden by your fundamental rights and freedoms.
Our legitimate interests are:
Providing and improving our platform: Our aim is to deliver secure, reliable and efficient services to our users. To that end, we will capture some personal data to improve platform functionality, security and user experience.
Marketing and communications: we may process your personal data for our marketing and communications purposes. This will happen where we have relevant updates or information about platform features, services or changes to existing partner organisations. For more information about our use of data for marketing, including the possibility of withdrawing from receiving communications, please see section 3 of this Privacy Notice.
3. How do we use your data for marketing including direct marketing?
We may process your data for marketing purposes. Marketing communications that you receive from us may include but it is not limited to offer about our products and services, primarily via email.
For these communications, we use your personal data as described in section 2 above. We rely on your consent or our legitimate interests to process your personal data to send you these communications.
You will always have the option to withdraw/opt-out from receiving marketing communications from us. To do so, you can reach out to us at: info@informationgovernanceservices.com. You can also unsubscribe from email marketing preferences by clicking on unsubscribe link in email.
Besides direct marketing communications, some of the data we collect via cookies when you browse our website may be used for marketing and analytics purposes. Please see our Cookie Policy on [INSERT LINK] for more details on the cookies we use and your related rights.
4. Do we collect or use personal information about children?
We do not provide services targeted at children and therefore, do not collect or use personal information about children.
5. How long do we keep your data?
We only keep your personal data for as long as it is needed to meet the purposes we specified above. Once your personal data is no longer needed, we securely anonymise and/or delete your personal data. Anonymising your data means that we apply a process to your data that prevents us from identifying you from that information.
If we rely on your consent to process your personal data, we will only store your data for as long as you consent to us holding it.
Overall, when determining the relevant retention periods for personal data, we will take the following factors into account:
The purposes for which the personal data are being processed;
Whether we have consent from you to store your personal data;
Legal or regulatory requirements;
Statute of limitations under applicable laws;
Legal claims or potential disputes;
Requests to have the personal data deleted; and
Guidelines issued by the relevant data protection authorities and industry standards.
6. With whom do we share your personal data?
We work with third parties with whom we have a contractual relationship to help us process your data for the proper functioning of the platform and fulfil the purposes specified above. Where information is shared, it will be done on strictly need-to-know basis and limited to what is necessary. As such, all personal data will only be shared in order to facilitate or assist with our contractual, legal obligations or identified legitimate interest.
A list of our current service providers with whom your data may be shared, and the functions they undertake can be found below:
We are very careful when we choose these service providers and only transfer your data outside of the UK where we have a lawful way to do so. We take all reasonable steps to confirm that an equivalent level of data protection is ensured.
When we disclose your personal data to these service providers, they may only process your personal data under our instructions and to perform the tasks we require.
Additionally, we may disclose your personal data in connection with court orders, legal proceedings, government inquiries or law enforcement authorities. If we do share, for these purposes, we will rely on UK GDPR Article 6(1)(c) – legal obligation and do so in compliance with Schedule 1 of the Data Protection Act 2018.
7. How do we keep your information confidential and safe?
We take the security of your personal data very seriously. We ensure that it is protected with multiple levels of security, including 256-bit AES encryption at rest which is widely considered to be one of the most secure methods of protecting data, and access controls. Access controls ensure that only a limited number of people have access to your data.
We ensure that all personal data is backed up, and we have a business continuity plan in place. In the event of an unexpected disruption to our service and business operation, we will be able to restore availability.
We store your data in data centres that are accredited to international and industry specific compliance standards such as ISO 27001:2022, SOC 2 Type I and Type II and SOC 3 certifications.
8. Your data subject rights
As a data subject, you have various rights about how your personal data is used.
You can find out more about your rights by visiting the Information Commissioner’s Office’s website in this link.
9. How can you exercise your rights?
If you want to make use of your rights where we are the data controller, you can exercise your rights by using our contact details displayed within section 15 of this Privacy Notice (“How can you contact us?”).
10. What is the timeframe for receiving a response?
We will always aim to respond to your request as soon as we can, and always within one month upon receipt of the request.
In certain circumstances, we are entitled to extend this period by another two months. This will be the case where your request is complex. We will notify you about this extension as soon as we can.
11. Verifying your identity
In order to comply with your request, we will need to verify your identity. This will be done so that we do not accidentally disclose your personal information to an unauthorised person. To that end, we may ask for confirmation of your identity as part of the process which may include requesting further documentation and processing of personal information where we have reasonable doubts about your identity.
12. When can we refuse to comply with your requests or charge a fee?
Usually, we will comply with your requests without undue delay and free of charge. However, there are certain circumstances where we are legally allowed to refuse to comply or charge a reasonable fee. This will be the case where your request is manifestly unfounded or excessive. If we decide to refuse to comply or charge you a reasonable fee, we will inform you about our decision.
Furthermore, your right to object might be further restricted if the processing is occurring for historical or scientific research purposes. You can read more about this restriction on the ICO’s website.
13. Do we make decisions based solely on automated processing?
We do not make decisions based on automated processing without human involvement.
14. Making a complaint
Should you have any queries about the how your information is used, or wish to make a complaint about how your data has been used, then please contact our team at: info@informationgovernanceservices.com
If you are unhappy with the way we use your information or about our response to your request, you have the option of contacting the Information Commissioner’s Office (ICO), who is the UK’s independent data protection supervisory authority. The ICO has multiple ways of which they can be contacted, including telephone and live chat. More information about how you can get in contact with the ICO can be found below:
Address:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone number: 0303 123 1113 (local rate)
Online: you can make a complaint or raise a concern via the ICO’s website.
15. How can you contact us?
If you would like to contact us in respect of any element of this Privacy Notice, or where you wish to raise a complaint or grievance, you can do so using the contact details provided below:
Address:
Furlong House
10A Chandos Street
London
W1G 9DQ
United Kingdom
Phone Number: 0208 106 7936
E-mail:info@informationgovernanceservices.com
16. Changes to this Notice
We may update this Notice from time to time. If we make any material changes to this Notice, we will change the “last updated” date of the Notice and notify you by your chosen form of communication, where applicable and appropriate. Changes to this Notice are effective when they are posted on this page.